Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LiteLLM Gateways’ Admin Key Vulnerability Exposed

LiteLLM Gateways’ Admin Key Vulnerability Exposed

Posted on September 10, 2026 By CWS

In February, Wiz Research discovered that nearly 10% of LiteLLM servers accessible from the internet accepted an example admin key, sk-1234. This key, included in LiteLLM’s setup guide, serves as a gateway administrator credential, allowing access to sensitive data stored on the server. Anyone possessing this key can potentially read API keys and cloud IAM credentials on the host machine.

Exposed LiteLLM Servers: A Detailed Look

Wiz’s scan identified 3,074 LiteLLM gateways on Shodan, with 294 accepting the example key. Of these, 191 did not have any key set, accepting any input, while the remainder retained the default setup guide value. A subsequent scan in August revealed over 85,000 instances, though most appeared to be honeypots or test systems, making direct comparisons difficult. As of September 9, the setup guide still advised users to replace sk-1234 with a random value prior to deployment.

The Critical Role of the Admin Key

The admin key in LiteLLM acts both as a credential and a key to enable authentication. In versions prior to 1.82.0-stable, gateways without a set master key automatically granted full admin rights. This access allows manipulation of API keys, viewing prompts and responses, and connecting to internal tools via the Model Context Protocol (MCP). Such vulnerabilities can lead to unauthorized usage of resources, termed LLMjacking, affecting the host’s cloud billing.

Additional Security Concerns and Flaws

LiteLLM’s ability to create pass-through endpoints poses further risk, as it allows administrators to forward requests to any URL, including private and cloud metadata addresses, potentially exposing IAM credentials. While no direct exploitations of this feature have been reported, it remains a significant concern. Wiz’s report also highlighted other vulnerabilities, including a post-authentication code execution flaw (CVE-2026-59821) and a guardrail sandbox escape (CVE-2026-40217), which have since been addressed in updates.

Despite these fixes, a separate flaw (CVE-2026-59822), allowing unauthorized MCP session access, continues to threaten LiteLLM. This vulnerability, exploited by attackers since July, enables unauthorized access to MCP tools using minimal bearer tokens.

Recommended Security Measures

Users are advised to upgrade to LiteLLM version 1.84.0 or later to mitigate known vulnerabilities. Additionally, changing the default admin key to a secure, random value is crucial. Blocking specific endpoints and restricting network access further enhance security. For systems that may have been compromised, reviewing and resetting key configurations is essential to restoring integrity. LiteLLM does not view the pass-through endpoint as a flaw, so network and IAM role restrictions remain the primary defenses.

As security threats continue to evolve, organizations must remain vigilant in their efforts to safeguard AI gateways and sensitive data.

The Hacker News Tags:admin key, AI gateway, API security, cloud security, CVE, IAM credentials, LiteLLM, Security, Vulnerability, Wiz Research

Post navigation

Previous Post: September 2026 Android Security Update Released
Next Post: New Zero-Day Exploit ‘ShieldCrash’ Hits Microsoft Defender

Related Posts

Supply Chain Attack Targets TanStack and AI Packages Supply Chain Attack Targets TanStack and AI Packages The Hacker News
LeakNet Ransomware Adopts ClickFix for Attacks LeakNet Ransomware Adopts ClickFix for Attacks The Hacker News
Why Executives and Practitioners See Risk Differently Why Executives and Practitioners See Risk Differently The Hacker News
SourTrade Campaign Uses Malvertising for Malware Assembly SourTrade Campaign Uses Malvertising for Malware Assembly The Hacker News
ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files The Hacker News
Silver Dragon APT41 Targets Governments with Advanced Techniques Silver Dragon APT41 Targets Governments with Advanced Techniques The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mac Users Targeted by Fake AI Installers with Malware
  • Cisco Secure FMC Vulnerability Actively Exploited
  • Anthropic Reports Fourth AI Security Breach with Claude Model
  • Leading Server Security Solutions for 2026
  • New Zero-Day Exploit ‘ShieldCrash’ Hits Microsoft Defender

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mac Users Targeted by Fake AI Installers with Malware
  • Cisco Secure FMC Vulnerability Actively Exploited
  • Anthropic Reports Fourth AI Security Breach with Claude Model
  • Leading Server Security Solutions for 2026
  • New Zero-Day Exploit ‘ShieldCrash’ Hits Microsoft Defender

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark